openSUSE Security Update : GraphicsMagick (openSUSE-2016-984)

High Nessus Plugin ID 92981


The remote openSUSE host is missing a security update.


This update for GraphicsMagick fixes the following issues :

- CVE-2014-9805: SEGV due to a corrupted pnm file (boo#983752)

- CVE-2016-5240: SVG converting issue resulting in DoS (endless loop) (boo#983309)

- CVE-2016-5241: Arithmetic exception (div by 0) in SVG conversion (boo#983455)

- CVE-2014-9846: Overflow in rle file (boo#983521)

- CVE-2015-8894: Double free in TGA code (boo#983523)

- CVE-2015-8896: Double free / integer truncation issue (boo#983533)

- CVE-2014-9807: Double free in pdb coder (boo#983794)

- CVE-2014-9809: SEGV due to corrupted xwd images (boo#983799)

- CVE-2014-9819: Heap overflow in palm files (boo#984142)

- CVE-2014-9835: Heap overflow in wpf file (boo#984145)

- CVE-2014-9831: Issues handling of corrupted wpg file (boo#984375)

- CVE-2014-9820: heap overflow in xpm files (boo#984150)

- CVE-2014-9837: Additional PNM sanity checks (boo#984166)

- CVE-2014-9815: Crash on corrupted wpg file (boo#984372)

- CVE-2014-9839: Theoretical out of bound access in via color maps (boo#984379)

- CVE-2014-9845: Crash due to corrupted dib file (boo#984394)

- CVE-2014-9817: Heap buffer overflow in pdb file handling (boo#984400)

- CVE-2014-9853: Memory leak in rle file handling (boo#984408)

- CVE-2014-9834: Heap overflow in pict file (boo#984436)

- CVE-2016-5688: Various invalid memory reads in ImageMagick WPG (boo#985442)

- CVE-2016-2317: Multiple vulnerabilities when parsing and processing SVG files (boo#965853)

- CVE-2016-2318: Multiple vulnerabilities when parsing and processing SVG files (boo#965853)


Update the affected GraphicsMagick packages.

See Also

Plugin Details

Severity: High

ID: 92981

File Name: openSUSE-2016-984.nasl

Version: $Revision: 2.6 $

Type: local

Agent: unix

Published: 2016/08/16

Modified: 2017/03/27

Dependencies: 12634

Risk Information

Risk Factor: High


Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P


Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: p-cpe:/a:novell:opensuse:GraphicsMagick, p-cpe:/a:novell:opensuse:GraphicsMagick-debuginfo, p-cpe:/a:novell:opensuse:GraphicsMagick-debugsource, p-cpe:/a:novell:opensuse:GraphicsMagick-devel, p-cpe:/a:novell:opensuse:libGraphicsMagick++-Q16-11, p-cpe:/a:novell:opensuse:libGraphicsMagick++-Q16-11-debuginfo, p-cpe:/a:novell:opensuse:libGraphicsMagick++-devel, p-cpe:/a:novell:opensuse:libGraphicsMagick-Q16-3, p-cpe:/a:novell:opensuse:libGraphicsMagick-Q16-3-debuginfo, p-cpe:/a:novell:opensuse:libGraphicsMagick3-config, p-cpe:/a:novell:opensuse:libGraphicsMagickWand-Q16-2, p-cpe:/a:novell:opensuse:libGraphicsMagickWand-Q16-2-debuginfo, p-cpe:/a:novell:opensuse:perl-GraphicsMagick, p-cpe:/a:novell:opensuse:perl-GraphicsMagick-debuginfo, cpe:/o:novell:opensuse:42.1

Required KB Items: Host/local_checks_enabled, Host/SuSE/release, Host/SuSE/rpm-list, Host/cpu

Patch Publication Date: 2016/08/15

Reference Information

CVE: CVE-2014-9805, CVE-2014-9807, CVE-2014-9809, CVE-2014-9815, CVE-2014-9817, CVE-2014-9819, CVE-2014-9820, CVE-2014-9831, CVE-2014-9834, CVE-2014-9835, CVE-2014-9837, CVE-2014-9839, CVE-2014-9845, CVE-2014-9846, CVE-2014-9853, CVE-2015-8894, CVE-2015-8896, CVE-2016-2317, CVE-2016-2318, CVE-2016-5240, CVE-2016-5241, CVE-2016-5688